Can not open encrypted files (EFS) (Urgent, please help)

Can not open encrypted files (EFS) (Urgent, please help)

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Can not open encrypted files (EFS) (Urgent, please help) persiancity 04-08-2006
Posted by persiancity on April 8, 2006, 6:14 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi there,

Please find My problem described here:


http://groups.google.com/group/comp.os.ms-windows.misc/browse_thread/...



At final, I find that I have to replace my Windows XP's account
Certificate with an old one, If I can assign a correct Certificate to
encrypted file then I guess that I am able to decrypt it, I have the
old cert. but:


I opened 'certmgr.msc' in MMC. In the "Personal\Certificates" and
"Trusted People\Certificates" I have TWO Certificates named 'ABC'. One
of them have the correct thumbprint (I am very happy that it exists!),
and another have a new thumbprint and as I see the 'Valid Date' started



from the what date I got the problem.


So, I export both Certificates into a safe place. Then I delete new
Certificate and re-login to the account, it create a new one with a new



new thumbprint instead of using the old Certificate that I guess (I am
sure) slove my problem.


I right-click on the new created Certificate icon and select:
All Tasks -> Renew Certificate with New Key


I am sure it's what I need but I got this message: "The wizard cannot
be started because it failed to contact the active directory."


The message title named "Certificate Renewal Wizard", I have not seen
it yet but I guess it'll let me to import old (CORRECT) certificate key



for new certificate. I am not sure that WinXP have Active Directory
installed, and can not find any option in Add/Remove too.


I need a way to renew an auto-created Certificate with an old one or
replace it for my account. Wizard didn't work to do it! :-|


Please tell me how I can replace/renew a Certificate in Windows XP.


Mehdi


Posted by Roger Abell [MVP] on April 8, 2006, 9:57 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Actually, it sounds as if you at some point changed the password of
the account via a reset, without use of the old password. At that time
access to the old EFS purposed cert became broken, and so, at the
next use of EFS a new cert was generated.
If you do have an export of the old cert, you could try clearing out
the new and/or useless certs and importing the old. You could test
importing the old first using a freshly defined account into which you
would import the cert.
As an alternative, if the cause is a password reset, then if you can
remember the old password, changing back to it may make the old
cert again functional (if you clear the new that by what you have said
is now there out of the way)
> Hi there,
>
> Please find My problem described here:
>
>
> http://groups.google.com/group/comp.os.ms-windows.misc/browse_thread/...
>
>
>
> At final, I find that I have to replace my Windows XP's account
> Certificate with an old one, If I can assign a correct Certificate to
> encrypted file then I guess that I am able to decrypt it, I have the
> old cert. but:
>
>
> I opened 'certmgr.msc' in MMC. In the "Personal\Certificates" and
> "Trusted People\Certificates" I have TWO Certificates named 'ABC'. One
> of them have the correct thumbprint (I am very happy that it exists!),
> and another have a new thumbprint and as I see the 'Valid Date' started
>
>
>
> from the what date I got the problem.
>
>
> So, I export both Certificates into a safe place. Then I delete new
> Certificate and re-login to the account, it create a new one with a new
>
>
>
> new thumbprint instead of using the old Certificate that I guess (I am
> sure) slove my problem.
>
>
> I right-click on the new created Certificate icon and select:
> All Tasks -> Renew Certificate with New Key
>
>
> I am sure it's what I need but I got this message: "The wizard cannot
> be started because it failed to contact the active directory."
>
>
> The message title named "Certificate Renewal Wizard", I have not seen
> it yet but I guess it'll let me to import old (CORRECT) certificate key
>
>
>
> for new certificate. I am not sure that WinXP have Active Directory
> installed, and can not find any option in Add/Remove too.
>
>
> I need a way to renew an auto-created Certificate with an old one or
> replace it for my account. Wizard didn't work to do it! :-|
>
>
> Please tell me how I can replace/renew a Certificate in Windows XP.
>
>
> Mehdi
>



Similar ThreadsPosted
User permission to open Open files in Computer Management May 16, 2008, 4:56 am
How to Copy EFS(encrypted) Files.... December 5, 2005, 1:45 pm
Cannot decrypt about 5% of encrypted files March 29, 2007, 10:22 am
Access encrypted files September 8, 2007, 11:56 am
Recovering encrypted files after reinstalling Windows August 19, 2006, 1:44 am
How to give multiple users access to encrypted files. June 26, 2006, 6:22 pm
No longer able to open CHM files June 30, 2005, 11:10 am
Can't Open Downloaded Files November 13, 2005, 4:22 am
Close open Files February 13, 2008, 3:18 am
rmtshare - open files December 8, 2008, 5:43 pm

The site map in XML format XML site map

Contact Us | Privacy Policy